Paymob for WooCommerce 这款 WordPress 插件在 4.1.9 版本之前存在严重安全漏洞。具体来说,插件在公共、无需身份验证的支付回调处理中,未对客户端提供的标识符进行适当清理,就将其直接用于 SQL 查询,并且该查询在执行前未验证支付提供商的 HMAC 签名。此漏洞允许未经身份验证的攻击者通过带外(反射式)和基于时间的盲注两种方式进行 SQL 注入,从而从数据库中读取任意数据,包括用户凭据和其他敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Paymob for WooCommerce | < 4.1.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Paymob for WooCommerce | 0 ~ 4.1.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16739 | Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery | |
| CVE-2026-14290 | Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Att | |
| CVE-2026-18039 | Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom P |
No comments yet